feat(player): cap streaming bandwidth with a user-chosen bitrate ceiling

Video streams were opened at a fixed allowance nobody could change:
MaxStreamingBitrate=20000000/VideoBitrate=18000000 on the HLS transcode
URL, 20 Mbps in the PlaybackInfo negotiation, and a 999999999 device
profile that let the server direct-play a source of any size. On a
metered or slow connection there was no way to spend less.

StreamingQuality is a ladder of bandwidth ceilings — Original, 20/10/8/
4/2/1 Mbps and 720 kbps — where a step bundles the total ceiling, the
audio share of it and the resolution that budget can carry. Those
numbers are Jellyfin encoding vocabulary, so they live in Rust and the
frontend only names a variant; labels and details come back over IPC
from player_get_streaming_qualities, the same arrangement as the EQ
presets.

The cap has to reach the *negotiation*, not just the transcode URL:
max_static_bitrate in the device profile is what makes the server refuse
to direct-play a file fatter than the cap, and without it a 30 Mbps
remux is handed over untouched and every URL parameter downstream is
moot. So it is applied at all four places that decide bandwidth — the
HLS URL builder, PlaybackInfo, the Live TV stream, and the
background-audio handoff (which takes the lower of the cap and its own
384 kbps). Video bitrate is the total minus the audio share so the two
together honour the ceiling rather than overshooting it.

The ceiling is process-wide rather than a repository field: it is a
preference about this device's connection, must survive a repository
rebuilt on re-login, and every URL builder plus the negotiation have to
agree on it or the cap leaks. Same shape as INCLUDE_CATALOG_BROWSE.

Two ways in. Settings holds the durable default, persisted to
app_settings and restored at startup — unlike the rest of VideoSettings,
because a limit set for a metered connection that silently reverts to
uncapped on the next launch spends the user's data with no changed
setting to see. The in-player menu is the "this film, this connection"
override: a cap is a property of the stream the server is producing, so
it cannot apply to one already in flight — player_set_stream_quality
re-opens the stream at the new quality and resumes at the current
position, reloading the native backend itself and handing HTML5 a URL
for the same reloadSource primitive the audio-track switch uses.

Tests pin the URL parameters at a capped and an uncapped step, the
handoff taking the lower of the two, the ladder's internal consistency
(video + audio == cap, resolution descending with bitrate) and the
persisted token's round trip. The ceiling is process-wide, so the tests
that depend on it serialise on a guard that restores the default.

TRACES: UR-074 | DR-160 | UT-156, UT-157
This commit is contained in:
2026-08-15 16:34:56 +02:00
parent 9f5f57cba4
commit dda2ff86a3
9 changed files with 971 additions and 16 deletions
+129
View File
@@ -342,6 +342,29 @@ pub enum AudioTrackSwitchResponse {
},
}
/// Response for a mid-playback streaming-quality change.
///
/// Mirrors [`AudioTrackSwitchResponse`]: the backend decides whether the caller
/// has to reload anything, so no strategy branch lives in the UI.
///
/// TRACES: UR-074 | DR-160
#[derive(specta::Type, Debug, Serialize)]
#[serde(tag = "strategy", rename_all = "camelCase")]
pub enum StreamQualityResponse {
/// The native backend was reloaded here; nothing left for the frontend.
Native {
/// Position playback resumed at.
position: f64,
},
/// HTML5 must reload its element with this URL.
ReloadStream {
/// New stream URL, already transcoded to the requested ceiling.
new_url: String,
/// Position to resume from.
position: f64,
},
}
/// Helper function to create MediaItem from video request
///
/// PlayItemRequest is now video-only, so we create a video MediaItem.
@@ -1447,6 +1470,112 @@ pub async fn player_switch_audio_track(
}
}
/// Change the bandwidth ceiling of the video that is playing *right now*.
///
/// A cap is a property of the stream the server is producing, so unlike a volume
/// change it cannot be applied to a stream already in flight — the stream has to
/// be re-opened at the new quality and resumed at the current position. That is
/// the same reload the transcoded-seek and audio-track paths use, and the same
/// two-sided split: HTML5 gets the URL back and reloads its own element, while a
/// native backend is reloaded here.
///
/// The change applies to this playback *and* to everything started afterwards
/// (it sets the process-wide ceiling), but it is deliberately **not** persisted:
/// the in-player picker is a "this film, this connection" control, and the
/// durable default belongs to Settings. `player_set_video_settings` is the one
/// that writes to the database.
///
/// TRACES: UR-074 | DR-160
#[tauri::command]
#[specta::specta]
pub async fn player_set_stream_quality(
player: State<'_, PlayerStateWrapper>,
repository_manager: State<'_, super::repository::RepositoryManagerWrapper>,
video_settings: State<'_, VideoSettingsWrapper>,
repository_handle: String,
quality: crate::settings::StreamingQuality,
use_html5: bool,
current_position: Option<f64>,
media_source_id: Option<String>,
audio_stream_index: Option<i32>,
) -> Result<StreamQualityResponse, String> {
info!(
"[player_set_stream_quality] Switching to {} (use_html5: {}, position: {:?})",
quality.label(),
use_html5,
current_position
);
let repository = repository_manager
.0
.get(&repository_handle)
.ok_or("Repository not found - user may need to log in")?;
let jellyfin_item_id = {
let controller = player.0.lock().await;
let queue_arc = controller.queue();
let queue = queue_arc.lock().map_err(|e| e.to_string())?;
let current_item = queue.current().ok_or("No item currently playing")?;
if current_item.media_type != MediaType::Video {
return Err("Current item is not a video".to_string());
}
current_item
.jellyfin_id()
.ok_or("Current item has no Jellyfin ID")?
.to_string()
};
// Set the ceiling *before* building the URL — the builder reads it.
crate::repository::online::set_streaming_quality(quality);
{
let mut settings = video_settings.0.lock().map_err(|e| e.to_string())?;
settings.streaming_quality = quality;
}
let position = current_position.unwrap_or(0.0);
let new_url = repository
.get_video_stream_url(
&jellyfin_item_id,
media_source_id.as_deref(),
current_position,
audio_stream_index,
)
.await
.map_err(|e| format!("Failed to get video stream URL: {:?}", e))?;
if use_html5 {
return Ok(StreamQualityResponse::ReloadStream { new_url, position });
}
// Native backend (Android/ExoPlayer): stop, repoint the queue entry at the
// new URL, and reload — mirroring `VideoSeekStrategy::BackendReloadStream`.
// The URL already carries `StartTimeTicks`, so the reloaded stream begins at
// the current position rather than at zero.
{
let controller = player.0.lock().await;
controller.stop().map_err(|e| e.to_string())?;
let queue_arc = controller.queue();
{
let mut queue = queue_arc.lock().map_err(|e| e.to_string())?;
if !queue.update_current_stream_url(new_url.clone()) {
return Err("Failed to update stream URL in queue".to_string());
}
}
let queue = queue_arc.lock().map_err(|e| e.to_string())?;
let updated_item = queue.current().ok_or("No current item after URL update")?;
controller
.load_and_play(updated_item)
.map_err(|e| e.to_string())?;
}
Ok(StreamQualityResponse::Native { position })
}
#[tauri::command]
#[specta::specta]
pub async fn player_set_audio_track(
+131 -3
View File
@@ -1,12 +1,29 @@
//! Audio and video playback settings commands.
//!
//! TRACES: UR-022, UR-027, UR-031, UR-032, UR-033 | DR-025, DR-030, DR-034, DR-035, DR-036, IR-020
//! TRACES: UR-022, UR-027, UR-031, UR-032, UR-033, UR-074 | DR-025, DR-030, DR-034, DR-035, DR-036, DR-160, IR-020
use tauri::State;
use std::sync::Arc;
use log::{info, warn};
use tauri::{Manager, State};
use super::{PlayerStateWrapper, VideoSettingsWrapper};
use crate::commands::storage::DatabaseWrapper;
use crate::player::AutoplaySettings;
use crate::settings::{AudioSettings, EqPreset, VideoSettings};
use crate::settings::{AudioSettings, EqPreset, StreamingQuality, VideoSettings};
use crate::storage::db_service::{DatabaseService, Query, QueryParam};
use crate::utils::lock::MutexSafe;
/// `app_settings` key holding the persisted streaming bandwidth ceiling.
///
/// The cap is persisted (unlike the rest of `VideoSettings`, which is
/// process-lifetime state) because forgetting it is the one failure that costs
/// the user something real: a limit set for a metered connection that silently
/// reverts to uncapped on the next launch spends their data allowance without
/// ever showing them a changed setting.
///
/// TRACES: UR-074 | DR-160
const STREAMING_QUALITY_KEY: &str = "streaming_quality";
#[tauri::command]
#[specta::specta]
@@ -54,6 +71,7 @@ pub async fn player_get_audio_settings(
pub async fn player_set_video_settings(
video_settings: State<'_, VideoSettingsWrapper>,
player: State<'_, PlayerStateWrapper>,
db: State<'_, DatabaseWrapper>,
settings: VideoSettings,
) -> Result<VideoSettings, String> {
let validated = settings.with_countdown_clamped();
@@ -62,6 +80,12 @@ pub async fn player_set_video_settings(
*current = validated.clone();
} // Drop MutexGuard before await
// The bandwidth ceiling is read by the repository's URL builders and by the
// PlaybackInfo negotiation, neither of which can see this wrapper.
// TRACES: UR-074 | DR-160
crate::repository::online::set_streaming_quality(validated.streaming_quality);
persist_streaming_quality(&db, validated.streaming_quality).await;
// Sync to PlayerController's autoplay settings so on_playback_ended() uses current values
let controller = player.0.lock().await;
controller.set_autoplay_settings(AutoplaySettings {
@@ -73,6 +97,110 @@ pub async fn player_set_video_settings(
Ok(validated)
}
/// The bandwidth ceilings the quality picker may offer, each with the label and
/// one-line detail to show for it, highest first.
///
/// The ladder and its numbers are Jellyfin encoding domain vocabulary, so the
/// frontend reads them here rather than encoding them — the same arrangement as
/// [`player_get_eq_presets`].
///
/// TRACES: UR-074 | DR-160
#[tauri::command]
#[specta::specta]
pub async fn player_get_streaming_qualities(
) -> Result<Vec<(StreamingQuality, String, String)>, String> {
Ok(StreamingQuality::ALL
.iter()
.map(|q| (*q, q.label().to_string(), q.detail().to_string()))
.collect())
}
/// Write the ceiling to `app_settings`. Failure is logged, not returned: the
/// setting has already been applied in memory, and refusing the whole call
/// because the write failed would leave the UI showing a cap that *is* active.
///
/// TRACES: UR-074 | DR-160
async fn persist_streaming_quality(db: &State<'_, DatabaseWrapper>, quality: StreamingQuality) {
let db_service = {
let database = db.0.lock_safe();
Arc::new(database.service())
};
let encoded = match serde_json::to_string(&quality) {
Ok(value) => value,
Err(e) => {
warn!("[VideoSettings] Failed to encode streaming quality: {}", e);
return;
}
};
let query = Query::with_params(
"INSERT OR REPLACE INTO app_settings (key, value, updated_at)
VALUES (?, ?, CURRENT_TIMESTAMP)",
vec![
QueryParam::String(STREAMING_QUALITY_KEY.to_string()),
QueryParam::String(encoded),
],
);
if let Err(e) = db_service.execute(query).await {
warn!("[VideoSettings] Failed to persist streaming quality: {}", e);
}
}
/// Restore the persisted bandwidth ceiling at startup, into both the repository
/// (which enforces it) and `VideoSettings` (which the settings UI reads).
///
/// Called from the Tauri `setup` hook. A missing or unreadable row leaves the
/// default — uncapped — in place, so a database problem degrades to the old
/// behaviour rather than to an arbitrary limit.
///
/// TRACES: UR-074 | DR-160
pub async fn restore_streaming_quality(app: &tauri::AppHandle) {
let db_service = {
let Some(db) = app.try_state::<DatabaseWrapper>() else {
warn!("[VideoSettings] No database available; streaming quality stays uncapped");
return;
};
let database = db.0.lock_safe();
Arc::new(database.service())
};
let query = Query::with_params(
"SELECT value FROM app_settings WHERE key = ?",
vec![QueryParam::String(STREAMING_QUALITY_KEY.to_string())],
);
let stored: Option<String> = match db_service.query_optional(query, |row| row.get(0)).await {
Ok(value) => value,
Err(e) => {
warn!("[VideoSettings] Failed to read streaming quality: {}", e);
return;
}
};
let Some(stored) = stored else { return };
let quality: StreamingQuality = match serde_json::from_str(&stored) {
Ok(quality) => quality,
Err(e) => {
warn!(
"[VideoSettings] Ignoring unrecognised persisted streaming quality {:?}: {}",
stored, e
);
return;
}
};
crate::repository::online::set_streaming_quality(quality);
if let Some(video_settings) = app.try_state::<VideoSettingsWrapper>() {
video_settings.0.lock_safe().streaming_quality = quality;
}
info!(
"[VideoSettings] Restored streaming quality cap: {}",
quality.label()
);
}
#[tauri::command]
#[specta::specta]
pub async fn player_get_video_settings(